1.打开防火墙 开启80端口、3306端口 :vi /etc/sysconfig/iptables
2.编辑
-A INPUT -mstate --state NEW -m tcp -p tcp --dport 80 -j ACCEPT #允许80端口通过防火墙
-A INPUT -mstate --state NEW -m tcp -p tcp --dport 3306 -j ACCEPT #允许3306端口通过防火墙
备注:很多网友把这两条规则添加到防火墙配置的最后一行,导致防火墙启动失败,
正确的应该是添加到默认的22端口这条规则的下面
如下所示:
################################添加好之后防火墙规则如下所示################################
# Firewallconfiguration written by system-config-firewall
# Manualcustomization of this file is not recommended.
*filter
:INPUTACCEPT [0:0]
:FORWARDACCEPT [0:0]
:OUTPUTACCEPT [0:0]
-A INPUT -mstate --state ESTABLISHED,RELATED -j ACCEPT
-A INPUT -picmp -j ACCEPT
-A INPUT -ilo -j ACCEPT
-A INPUT -mstate --state NEW -m tcp -p tcp --dport 22 -j ACCEPT
-A INPUT -mstate --state NEW -m tcp -p tcp --dport 80 -j ACCEPT
-A INPUT -mstate --state NEW -m tcp -p tcp --dport 3306 -j ACCEPT
-A INPUT -jREJECT --reject-with icmp-host-prohibited
-A FORWARD-j REJECT --reject-with icmp-host-prohibited
COMMIT
#######################################################################################
3.重启防火墙
/etc/init.d/iptablesrestart #最后重启防火墙使配置生效
4.
关闭SELINUX
vi/etc/selinux/config
#SELINUX=enforcing#注释掉
#SELINUXTYPE=targeted#注释掉
SELINUX=disabled#增加
:wq #保存退出
shutdown -rnow #重启系统